DefusedCyber Profile Banner
Defused Profile
Defused

@DefusedCyber

Followers
5K
Following
941
Media
198
Statuses
505

Managed Honeypots for Early-warning Threat Intelligence 🍯 Access free honeypot intel: https://t.co/TTnxgi9Hv5

Joined August 2023
Don't wanna be here? Send us removal request.
@DefusedCyber
Defused
8 days
🍯 New Defused Functionality! Automatically collect malware that gets embedded into exploit payloads 🧨 Gradually rolling out to Defused TF honeypots starting tomorrow! Subscribe today πŸ‘‰ https://t.co/vJlRQ5KUel
1
6
38
@DefusedCyber
Defused
1 day
Last minute honeypot alert before Christmas 🍯 Major enumeration sweep going on using PROPFIND, a WebDAV-specific HTTP verb. Enumeration happening from multiple IPs all from DigitalOcean servers geolocated in SGP - 159.223.71.35 188.166.219.249 157.230.44.100 139.59.123.216
0
9
27
@angryolditpers1
angry_old_it_person
4 days
A great reminder - do a few things and do them well vs we are going to do everything and suck at everything.
@DefusedCyber
Defused
6 days
0-Day Alert 🚨 Cisco warns of *unpatched* actively exploited zero-day in multiple Cisco Email Security products (CVE-2025-20393) We have just launched an Cisco ESA honeypot stream for monitoring - available now for Defused TF subscribers! 🍯 πŸ‘‰ https://t.co/GXFaqghsXI
0
1
4
@DefusedCyber
Defused
4 days
🚨 Attacks attempting exploitation of CVE-2025-20393 (Cisco Secure Email zero-day) are now attempting to drop AsyncOS-specific malware onto our honeypots 🍯 It is still unclear if the attacks are genuine - technical details of the vulnerability are not known to date
0
7
38
@cyb3rops
Florian Roth ⚑️
4 days
@DefusedCyber
Defused
6 days
0-Day Alert 🚨 Cisco warns of *unpatched* actively exploited zero-day in multiple Cisco Email Security products (CVE-2025-20393) We have just launched an Cisco ESA honeypot stream for monitoring - available now for Defused TF subscribers! 🍯 πŸ‘‰ https://t.co/GXFaqghsXI
8
48
385
@Viperion_OSINT
GHOST OPERATOR V
4 days
This is dope
@DefusedCyber
Defused
4 days
🍯 Multiple vulnerabilities are actively being exploited in Fortinet products! Monitor exploits hitting our honeypots in real time πŸ‘‰
1
2
5
@DefusedCyber
Defused
4 days
🍯 Multiple vulnerabilities are actively being exploited in Fortinet products! Monitor exploits hitting our honeypots in real time πŸ‘‰
@SimoKohonen
Simo
4 days
Interesting Fortinet payload... CVE-2025-58034 + CVE-2025-59718 chained together? I need to get some Fortinet boxes to start testing all these exploit cocktails getting thrown at the honeypots πŸ˜‚
0
4
24
@DefusedCyber
Defused
4 days
⚠️A tool has been released for automating the discovery of CVE-2025-20393 targets (Cisco Secure Email zero-day) We are seeing it chained with POST requests to implant C2 servers 🍯 This is likely not the genuine vulnerable path - technical details of the vulnerability are not
2
16
64
@SimoKohonen
Simo
5 days
Fortigate SSO pathway fingerprinting (CVE-2025-59718) is going on pretty actively... Just tweaked the honeypot responses to be a bit more favourable - lets see if we can tease out more actions from some of these actors 🍯
2
15
63
@0x_shaq
faulty *ptrrr
5 days
pov: you launched your 0day exploit on a random server but it’s @DefusedCyber honeypot and now your bug is burned
2
4
37
@DefusedCyber
Defused
6 days
0-Day Alert 🚨 Cisco warns of *unpatched* actively exploited zero-day in multiple Cisco Email Security products (CVE-2025-20393) We have just launched an Cisco ESA honeypot stream for monitoring - available now for Defused TF subscribers! 🍯 πŸ‘‰ https://t.co/GXFaqghsXI
1
14
73
@kmkz_security
kmkz
6 days
No malware. Just RCE -> reverse shell -> C2. Source domain taken down ? Well, infra still up and VT or EDR won't help This is real‑world initial access tradecraft baby! Observed on @DefusedCyber cc @SimoKohonen #OffensiveSecurity #CTI #RedTeam
4
12
72
@SimoKohonen
Simo
7 days
This may be the coolest thing ive built yet Running live on one honeypot now and seems to work nicely. Will take a bit to update the full fleet but we’ll get there 🍯
@DefusedCyber
Defused
8 days
🍯 New Defused Functionality! Automatically collect malware that gets embedded into exploit payloads 🧨 Gradually rolling out to Defused TF honeypots starting tomorrow! Subscribe today πŸ‘‰ https://t.co/vJlRQ5KUel
3
4
70
@nembo81pr
Simo
9 days
@DefusedCyber
Defused
9 days
🚨 CVE-2025-59718 (FortiCloud SSO login bypass) exploitation is under way - at least 7 different IPs exploiting our Fortinet honeypots over the weekend Example (decoded) payload: <samlp:Response xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol" ID="_bypass1337"
1
1
4
@DefusedCyber
Defused
9 days
🚨 CVE-2025-59718 (FortiCloud SSO login bypass) exploitation is under way - at least 7 different IPs exploiting our Fortinet honeypots over the weekend Example (decoded) payload: <samlp:Response xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol" ID="_bypass1337"
3
34
129
@DefusedCyber
Defused
12 days
🚨 React has disclosed two new, additional vulnerabilities to the critical RCE vuln of last week - CVE-2025-55183 and CVE-2025-55184. Patches are available and urged to be applied immediately. Track live attacks against React honeypots πŸ‘‰ https://t.co/GXFaqggV8a
0
19
84
@SimoKohonen
Simo
12 days
Public accountability post: there will be a cool @DefusedCyber release on Monday (stuck in overoptimization land again)
3
1
13
@DefusedCyber
Defused
12 days
🚨 Critical (CVSS 9.9) RCE vuln in SAP Solution Manager (CVE-2025-42880) allows an authenticated attacker to execute code. We have added it as a honeypot stream into Defused TF. 🍯 This vulnerability does not have a POC yet. Lets go hunting! πŸ‘‰ https://t.co/0KmalJdGuV
2
12
77
@SimoKohonen
Simo
13 days
Good to find an explanation why some madman threw thousands of random SOAP exploits at Ivanti honeypots today
@watchtowrcyber
watchTowr
13 days
Today, we’re releasing watchTowr Labs’ @chudyPB’s BlackHat .NET research, owning Barracuda, Ivanti and more solutions. Enjoy the read as Piotr explains a new .NET Framework primitive, used to achieve pre- and post-auth RCE on numerous enterprise appliances.
1
4
55
@DefusedCyber
Defused
14 days
Monitor threat intelligence for Ivanti-based attack vectors on Defused πŸ‘‰ https://t.co/GXFaqggV8a
0
0
2